Message ID | 20240820121526.380245-1-aha310510@gmail.com (mailing list archive) |
---|---|
State | Superseded |
Delegated to: | Netdev Maintainers |
Headers | show |
Series | net/smc: prevent NULL pointer dereference in txopt_get | expand |
On Tue, Aug 20, 2024 at 2:15 PM Jeongjun Park <aha310510@gmail.com> wrote: > > Since inet_sk(sk)->pinet6 and smc_sk(sk)->clcsock practically > point to the same address, when smc_create_clcsk() stores the newly > created clcsock in smc_sk(sk)->clcsock, inet_sk(sk)->pinet6 is corrupted > into clcsock. This causes NULL pointer dereference and various other > memory corruptions. > > To solve this, we need to modify the smc_sock structure. > > Reported-by: syzkaller <syzkaller@googlegroups.com> > Fixes: ac7138746e14 ("smc: establish new socket family") Are you sure this Fixes: tag is correct ? Hint : This commit is from 2017, but IPPROTO_SMC was added in 2024. > Signed-off-by: Jeongjun Park <aha310510@gmail.com> > --- > net/smc/smc.h | 5 ++++- > 1 file changed, 4 insertions(+), 1 deletion(-) > > diff --git a/net/smc/smc.h b/net/smc/smc.h > index 34b781e463c4..f23f76e94a66 100644 > --- a/net/smc/smc.h > +++ b/net/smc/smc.h > @@ -283,7 +283,10 @@ struct smc_connection { > }; > > struct smc_sock { /* smc sock container */ > - struct sock sk; > + union { > + struct sock sk; /* for AF_SMC */ > + struct inet_sock inet; /* for IPPROTO_SMC */ > + }; > struct socket *clcsock; /* internal tcp socket */ > void (*clcsk_state_change)(struct sock *sk); > /* original stat_change fct. */ > --
Eric Dumazet wrote: > > On Tue, Aug 20, 2024 at 2:15 PM Jeongjun Park <aha310510@gmail.com> wrote: > > > > Since inet_sk(sk)->pinet6 and smc_sk(sk)->clcsock practically > > point to the same address, when smc_create_clcsk() stores the newly > > created clcsock in smc_sk(sk)->clcsock, inet_sk(sk)->pinet6 is corrupted > > into clcsock. This causes NULL pointer dereference and various other > > memory corruptions. > > > > To solve this, we need to modify the smc_sock structure. > > > > Reported-by: syzkaller <syzkaller@googlegroups.com> > > Fixes: ac7138746e14 ("smc: establish new socket family") > > Are you sure this Fixes: tag is correct ? > > Hint : This commit is from 2017, but IPPROTO_SMC was added in 2024. > After listening, I realized that the Fixes tag was wrong. When sending the v7 patch, you only need to use the Fixes tag for the d25a92ccae6b commit, so we will send it by combining the existing patches. > > > Signed-off-by: Jeongjun Park <aha310510@gmail.com> > > --- > > net/smc/smc.h | 5 ++++- > > 1 file changed, 4 insertions(+), 1 deletion(-) > > > > diff --git a/net/smc/smc.h b/net/smc/smc.h > > index 34b781e463c4..f23f76e94a66 100644 > > --- a/net/smc/smc.h > > +++ b/net/smc/smc.h > > @@ -283,7 +283,10 @@ struct smc_connection { > > }; > > > > struct smc_sock { /* smc sock container */ > > - struct sock sk; > > + union { > > + struct sock sk; /* for AF_SMC */ > > + struct inet_sock inet; /* for IPPROTO_SMC */ > > + }; > > struct socket *clcsock; /* internal tcp socket */ > > void (*clcsk_state_change)(struct sock *sk); > > /* original stat_change fct. */ > > --
diff --git a/net/smc/smc.h b/net/smc/smc.h index 34b781e463c4..f23f76e94a66 100644 --- a/net/smc/smc.h +++ b/net/smc/smc.h @@ -283,7 +283,10 @@ struct smc_connection { }; struct smc_sock { /* smc sock container */ - struct sock sk; + union { + struct sock sk; /* for AF_SMC */ + struct inet_sock inet; /* for IPPROTO_SMC */ + }; struct socket *clcsock; /* internal tcp socket */ void (*clcsk_state_change)(struct sock *sk); /* original stat_change fct. */
Since inet_sk(sk)->pinet6 and smc_sk(sk)->clcsock practically point to the same address, when smc_create_clcsk() stores the newly created clcsock in smc_sk(sk)->clcsock, inet_sk(sk)->pinet6 is corrupted into clcsock. This causes NULL pointer dereference and various other memory corruptions. To solve this, we need to modify the smc_sock structure. Reported-by: syzkaller <syzkaller@googlegroups.com> Fixes: ac7138746e14 ("smc: establish new socket family") Signed-off-by: Jeongjun Park <aha310510@gmail.com> --- net/smc/smc.h | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) --